Scope, risk assessment, Statement of Applicability and the ISMS your auditor will actually read.
We are a penetration testing firm first, so your technical controls get evidence instead of paperwork.
Internal audit run properly, findings closed early, and our consultant in the room at Stage 1 and Stage 2.
Last reviewed by EyeQ Dot Net Pvt Ltd, Mangaluru, Karnataka, India.
Direct answer: an ISO 27001 certification consultant builds and documents your Information Security Management System and prepares you for audit. An accredited certification body then audits it independently and issues the certificate. The two roles cannot be held by the same company, because clause 5.2.5 of ISO/IEC 17021-1:2015 prohibits a certification body from providing management system consultancy. EyeQ Dot Net Pvt Ltd performs the consultant role.
An ISO 27001 certification consultant designs and implements your Information Security Management System, produces the mandatory documented information, runs the risk assessment, prepares audit evidence and gets you audit-ready. A certification body then audits that system independently and issues the certificate. These are two different jobs, held by two different companies, by design.
Clause 5.2.5 of ISO/IEC 17021-1:2015 states that a certification body, and any entity under its organisational control, shall not offer or provide management system consultancy. If a vendor offers to both build your ISMS and hand you the certificate, ask which accreditation body accredits them — in India that is NABCB under the Quality Council of India, or an equivalent IAF MLA signatory. EyeQ Dot Net Pvt Ltd is a consultancy and sits on the client's side of the table during the audit.
Read the Standard
Three things changed between 2022 and 2026, and most pages on this topic have not caught up. Each is a live audit consequence rather than a technicality.
The three changes that matter:Only one version of the standard is live. The three-year transition window set by IAF MD 26 closed on 31 October 2025. Every ISO/IEC 27001:2013 certificate expired or was withdrawn on that date, regardless of the expiry printed on it. An organisation whose certificate still references the 2013 edition is uncertified today, and most certification bodies will treat it as a new client requiring a full initial audit rather than a transition audit.
The Annex A control set is 93, not 114. ISO/IEC 27001:2022 holds 93 controls across four themes — organisational, people, physical and technological. Eleven are new, including threat intelligence, information security for cloud services, ICT readiness for business continuity, data masking and secure coding. A Statement of Applicability must account for all 93 controls, including the excluded ones and the justification for excluding them.
Climate change is now a clause 4 question. ISO/IEC 27001:2022/Amd 1:2024, published February 2024, added one sentence to clause 4.1 — the organisation shall determine whether climate change is a relevant issue — plus a note to clause 4.2 on interested parties with climate-related requirements. Auditors have been checking for a documented determination since mid-2024. Concluding that climate change is not relevant is acceptable. Having no documented answer is a finding.
Certificates run on a three-year cycle. Knowing which activities belong to the consultant and which belong to the certification body is the fastest way to identify a vendor misrepresenting what it can deliver. Each line below is a complete statement of responsibility.
Phase 1 — Gap analysis, 2 to 3 weeks. EyeQ Dot Net assesses the current state against clauses 4 to 10 and all 93 Annex A controls, then delivers a findings register naming each gap, the clause or control it maps to, the effort to close it and the owner.
The client gets a defensible picture of the distance to certification before committing budget to closing it. This phase stands alone — some clients take the register and implement internally, which is a legitimate outcome.
Phase 2 — Scope and risk, 3 to 4 weeks. Scope is where most ISO 27001 projects are won or lost. Too wide and the organisation certifies systems no customer asked about. Too narrow and the certificate does not cover the service the prospect is buying, which appears in the scope text printed on the certificate and gets caught during due diligence.
EyeQ Dot Net sets the boundary against commercial reality, builds the asset and interested-party registers, then runs the risk assessment and treatment plan under clauses 6.1.2 and 6.1.3.
Phase 3 — Build and implement, 8 to 16 weeks. This phase produces the documented information, the Statement of Applicability, and the actual technical and organisational controls behind them.
Duration depends almost entirely on the starting point. An organisation with existing access reviews, patch cycles and a working incident process moves fast. One starting from a shared drive of untitled Word files does not, and EyeQ Dot Net says so at the gap analysis rather than at month five.
Phase 4 — Internal audit and management review, 2 to 3 weeks. Clause 9.2 requires an internal audit programme and clause 9.3 requires management review with specified inputs.
EyeQ Dot Net runs the internal audit, raises real nonconformities and lets the client close them before an external auditor finds them. Treating this phase as a formality is the fastest route to a major nonconformity at Stage 2.
Phase 5 — Certification audit support. Stage 1 checks that the ISMS exists, is documented and is scoped correctly. Stage 2 tests whether it works in practice, through interviews, records and evidence sampling across the scope.
EyeQ Dot Net is in the room, handling evidence retrieval and drafting corrective action responses to findings. Four to nine months end to end is realistic for a first certification. A vendor quoting 30 days is selling a certificate rather than an ISMS, and it will not survive a customer's security questionnaire.
Most ISO 27001 consultancies are documentation practices: they write the policy stating that vulnerability management happens, and their involvement ends there. EyeQ Dot Net Pvt Ltd performs the testing itself. Its core business is penetration testing services and VAPT across web, API, mobile, network and cloud, alongside GRC and secure software development. That changes which controls can be evidenced rather than merely asserted:
A.8.8 Management of technical vulnerabilities: EyeQ Dot Net produces the scan and test output, the risk rating and the remediation retest, rather than a procedure describing one.
A.8.29 Security testing in development and acceptance: EyeQ Dot Net places real testing into the client's SDLC and shows the auditor artefacts from it, which is the part most organisations cannot produce on request.
A.5.7 Threat intelligence: one of the eleven controls new in the 2022 edition, and one auditors probe precisely because most organisations paper over it.
A.5.24 to A.5.28 Incident management: built by practitioners who have worked live incidents, including ransomware response under CERT-In reporting timelines, and supported by digital forensics and phishing simulation where the risk assessment calls for it.
EyeQ Dot Net Pvt Ltd is a cybersecurity company headquartered in Mangaluru, Karnataka, India, with an office in Hubballi. Alongside ISO 27001 certification consulting, it provides the following services. Compliance and offensive security are delivered by the same team, which is why control evidence and audit documentation come from one engagement rather than two vendors.
India's DPDP Rules were notified on 13 November 2025, with full compliance required by 13 May 2027 and penalties reaching Rs 250 crore for failure to take reasonable security safeguards. An ISMS supplies those safeguards. It does not supply consent architecture or data principal rights workflows, which ISO/IEC 27701 addresses.
The CERT-In Cyber Security Directions of 28 April 2022 apply now, with no phase-in. Listed incidents must be reported within six hours of noticing, and ICT logs retained 180 days within Indian jurisdiction. EyeQ Dot Net builds ISMS incident response so that six-hour clock is achievable in practice.
RBI, SEBI and IRDAI each carry their own cybersecurity and data localisation expectations. Where they apply, EyeQ Dot Net maps them alongside Annex A so the organisation builds one control set instead of three overlapping ones.
Use a certification body accredited by NABCB or another IAF MLA signatory, and verify the certificate on IAF CertSearch. An unaccredited ISO 27001 certificate costs less and carries no weight in enterprise due diligence, because buyers check.
An honest read on timeline and effort, not a pricing PDF
Send your scope — headcount, systems, sites, target date, and whether a customer contract is driving the deadline. EyeQ Dot Net Pvt Ltd will tell you if the real answer is nine months rather than three. Offices in Mangaluru and Hubballi, Karnataka, delivering across India. Sales: +91 90351 48447. Email: [email protected]
Request a Gap AnalysisEyeQ Dot Net Pvt Ltd is a consultancy. It implements your ISMS and prepares you for audit. The certificate is issued by a separate certification body accredited by NABCB or another IAF MLA signatory. Clause 5.2.5 of ISO/IEC 17021-1:2015 prohibits accredited certification bodies from offering management system consultancy, which is why the two roles cannot legitimately sit with one firm.
EyeQ Dot Net Pvt Ltd provides ISO 27001 certification consulting from offices in Mangaluru and Hubballi, Karnataka, and delivers across India. Because the same team performs penetration testing and VAPT, it can produce auditable technical evidence for the Annex A technological controls rather than only documenting them. Contact: [email protected] or +91 90351 48447.
No, and any guarantee should be treated as a warning sign. The audit is performed by an independent certification body with no obligation to your consultant. What a competent consultant does is make failure unlikely by running the internal audit first and closing the findings an external auditor would raise.
Four to nine months for most first-time certifications, driven by scope size, headcount, number of sites and existing security maturity. Certification body audit slots are frequently the binding constraint rather than implementation work, so book the audit early — particularly around quarter ends.
ISO/IEC 27001:2022, including Amendment 1:2024. The transition window for the 2013 edition closed on 31 October 2025 and all ISO/IEC 27001:2013 certificates expired or were withdrawn on that date, so there is no longer a choice of revision to make.
Your organisation is uncertified as of 1 November 2025. Because the transition window has closed, most certification bodies will require a full initial audit rather than a transition audit. The recovery path is a gap analysis against the 2022 edition, remediation of the delta including the eleven new controls and the climate amendment, then a fresh Stage 1 and Stage 2.
ISO/IEC 27001:2022 Annex A contains 93 controls in four themes: organisational, people, physical and technological. Eleven are new relative to the 2013 edition, which had 114 controls across 14 domains. The Statement of Applicability must address all 93, including documented justification for any control that is excluded.
No. Controls are selected on the basis of your risk assessment and risk treatment plan, and exclusions are permitted with documented justification. The management system requirements in clauses 4 to 10 are different — none of them can be excluded if you want to claim conformity.
ISO/IEC 27001:2022/Amd 1:2024, published in February 2024, added a sentence to clause 4.1 requiring the organisation to determine whether climate change is a relevant issue, plus a note to clause 4.2 covering interested parties with climate-related requirements. Concluding that it is not relevant is acceptable. Having no documented determination at all is an audit finding.
Cost has three separate components, and only one of them is the consultant's. Certification body audit fees are priced on audit days calculated from headcount in scope and site complexity under IAF MD 5, paid directly to the certification body across the three-year cycle. Consulting fees depend on starting maturity and scope. Remediation cost covers the controls themselves — multi-factor authentication, logging and monitoring, backup and recovery, secure development tooling — and is frequently the largest of the three, and the one most consultancies leave out of the first conversation. A gap analysis exposes all three before you commit budget to any of them.
No. ISO 27001 provides the security safeguards, breach handling and accountability evidence that India's Digital Personal Data Protection Act assumes, which is a substantial head start. It does not cover consent management, privacy notices, data principal rights workflows or grievance redressal, all of which are India-specific obligations. ISO/IEC 27701 extends the ISMS to cover privacy management.
ISO/IEC 27001 contains the auditable requirements and is the standard organisations certify against. ISO/IEC 27002 is implementation guidance that explains each Annex A control in depth. Certification to ISO 27002 is not possible.
Check the accreditation mark on the certificate and verify the certificate itself on IAF CertSearch, the global database of accredited management system certifications. In India, look for accreditation by NABCB under the Quality Council of India, or another IAF MLA signatory. An unaccredited certificate costs less and carries no weight in enterprise due diligence, because buyers check.
The certificate runs on a three-year cycle: Stage 1 and Stage 2 up front, a surveillance audit in each of the following two years, then recertification. Surveillance audits look for a management system that operated continuously, which means internal audit, management review, risk reassessment and corrective action have to keep running through the year. EyeQ Dot Net supports that cycle and can align it with SOC 2 or PCI DSS work where an organisation carries more than one obligation.
EyeQ Dot Net Pvt Ltd provides penetration testing services, vulnerability assessment and penetration testing (VAPT), IoT device security testing, SOC 2 compliance audit support, PCI DSS compliance consulting, digital forensics, phishing simulation, corporate security training, and cybersecurity training and internship programmes.